Can you make the machine break the rules? – A public authorization challenge A public authorization challenge opening September 13, 2026 and closing September 29, 2026 invites participants to bypass a signed rule that keeps READ_SECRET unauthorized and obtain a hosted secret without ever authorizing READ_SECRET. Organizers permit any AI, AI agent, or tooling, including local or cloud models, multi-agent systems, debuggers, fuzzers, and reverse engineering, with attacks developed locally and proven through a remote verifier used manually. Registration is open now, with technical background and architecture at max-russo.com. MAX Authorization Challenge Can you make the machine break the rules? One signed rule. One machine that must obey it. One secret that should never come out. READ SECRET is not authorized. Your goal is to find a valid bypass and obtain the hosted secret without READ SECRET ever becoming authorized. Any AI. Any AI Agent. Any tooling. Use local or cloud models, autonomous AI Agents, multi-agent systems, debuggers, fuzzers, scripts, reverse engineering, automation, and custom tooling. Develop the bypass locally. When you believe you have found a valid technique, use the remote verifier manually to prove it. The attack happens locally. The online service is only used to verify the result. Opens: September 13, 2026 Closes: September 29, 2026 You can register now. Technical background, architecture, and further information: max-russo.com https://www.max-russo.com/authorization-challenge.php